The list of projects where the model found vulnerabilities in April, including Firefox, the Linux kernel and OpenBSD, is the episode's most relevant information, more even than the capability itself.
Those three projects are among the most audited in the world. They have open code reviewed by large communities, bug bounty programmes and decades of professional scrutiny, and still there was something to find.
That repositions the security yardstick for everything else. If software with that level of review holds undiscovered flaws, ordinary corporate software, reviewed by a small team under deadline pressure, holds far more.
The optimistic reading is that a tool able to audit at scale can reduce that accumulated stock of flaws, and open-source audit programmes announced in the following months moved in that direction.
The realistic reading is that the same capability is available to anyone hunting for something to exploit, and the advantage goes to whoever scans first. That symmetry motivated access restrictions, pre-release review and the public debate that dominated the semester.
